T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from an external server and immediately execute their contents using Bash or PowerShell. Neither command pins a specific release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded script before execution.
HTTPS protects the connection in transit but does not guarantee that the remote server, hosting account, installation script, or upstream release process has not been compromised. Because the retrieved payload can change after the Skill has been reviewed, its effective behavior cannot be determined from the audited package alone.
Installing the
ooCLI supports the Skill's declared purpose, but piping an unverified remote response directly into a shell exceeds the minimum mechanism necessary to perform that installation. A pinned, independently verified artifact would provide the same functionality with a smaller supply-chain risk.Attack Path
- The
oocommand is absent, causing anoo: command not founderror. - The Agent or user follows the first-time setup instructions in
SKILL.md. - An attacker compromises the OOMOL distribution server, DNS or hosting infrastructure, installation-script publishing process, or another relevant supply-chain component.
- The attacker replaces the remotely served installer with a malicious script.
curl | bashorirm | iexpasses that script directly to a command interpreter without integrity verification.- The malicious payload executes with all permissions available to the user or process that invok ...[truncated 736 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-shell installation commands.
- Pin installation instructions to a specific, immutable CLI release and official artifact URL.
- Download the artifact to a local file without executing it immediately.
- Publish and require verification of a SHA-256 checksum or, preferably, a cryptographic signature whose trusted public key is distributed through a separate channel.
- Abort installation if verification fails.
- Allow the downloaded script or package to be inspected before execution.
- Prefer a trusted operating-system package manager with explicit version pinning and package-signature verification.
- Instruct users not to run the installer as an administrator or with
sudounless a documented installation step strictly requires elevation. - Document the files, directories, and permissions modified by installation so users can evaluate the required privilege scope.
